USN-4897-1: Pygments vulnerability
Ben Caller discovered that Pygments incorrectly handled parsing certain files. If a user or automated system were tricked into parsing a specially crafted file, a remote attacker could cause Pygments to hang or consume resources, resulting in a denial of service.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this Pygments vulnerability?
The vulnerability ID for this Pygments vulnerability is CVE-2021-27291.
What is the impact of the Pygments vulnerability?
The Pygments vulnerability can result in a denial of service by causing Pygments to hang or consume excessive resources.
Which versions of Python-Pygments are affected by this vulnerability?
The versions affected by this vulnerability are python-pygments version 2.3.1+dfsg-1ubuntu2.2, python-pygments version 2.2.0+dfsg-1ubuntu0.2, and python-pygments version 2.1+dfsg-1ubuntu0.2.
Which versions of Python3-Pygments are affected by this vulnerability?
The versions affected by this vulnerability are python3-pygments version 2.3.1+dfsg-4ubuntu0.2, python3-pygments version 2.3.1+dfsg-1ubuntu2.2, python3-pygments version 2.2.0+dfsg-1ubuntu0.2, and python3-pygments version 2.1+dfsg-1ubuntu0.2.
How do I fix the Pygments vulnerability?
To fix the Pygments vulnerability, update to the appropriate fixed versions: python-pygments version 2.3.1+dfsg-1ubuntu2.2, python-pygments version 2.2.0+dfsg-1ubuntu0.2, python-pygments version 2.1+dfsg-1ubuntu0.2, python3-pygments version 2.3.1+dfsg-4ubuntu0.2, python3-pygments version 2.3.1+dfsg-1ubuntu2.2, python3-pygments version 2.2.0+dfsg-1ubuntu0.2, or python3-pygments version 2.1+dfsg-1ubuntu0.2.